Vulnerability index

Browse CVEs

14 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dnf5 HIGH 8.4
CVE-2024-1929

Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a malicious user to impact Confidentiality and Integrity v…

Fix: 5.1.17+
Fix from $1,950 2024-05-08
Libcomps HIGH 8.8
CVE-2019-3817

A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an app…

Fix: 0.1.10+
Fix from $1,950 2019-03-27
Rpm HIGH 7.8
CVE-2017-7500

It was found that rpm did not properly handle RPM installations when a destination path was a symbolic link to a directory, possibly changing ownersh…

Fix: 4.13.0.2+
Fix from $1,950 2018-08-13
Rpm HIGH 7.8
CVE-2017-7501

It was found that versions of rpm before 4.13.0.2 use temporary files with predictable names when installing an RPM. An attacker with ability to writ…

Fix: 4.13.0.3+
Fix from $1,950 2017-11-22
Rpm HIGH 10.0
CVE-2014-8118EPSS 8%

Integer overflow in RPM 4.12 and earlier allows remote attackers to execute arbitrary code via a crafted CPIO header in the payload section of an RPM…

Fix: after 4.12.0
Fix from $1,950 2014-12-16
Rpm MEDIUM 6.8
CVE-2012-0060

RPM before 4.9.1.3 does not properly validate region tags, which allows remote attackers to cause a denial of service (crash) and possibly execute ar…

Fix: after 4.9.1.2
Fix from $1,600 2012-06-04
Rpm MEDIUM 6.8
CVE-2012-0061

The headerLoad function in lib/header.c in RPM before 4.9.1.3 does not properly validate region tags, which allows user-assisted remote attackers to …

Fix: after 4.9.1.2
Fix from $1,600 2012-06-04
Rpm MEDIUM 6.8
CVE-2012-0815

The headerVerifyInfo function in lib/header.c in RPM before 4.9.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute…

Fix: after 4.9.1.2
Fix from $1,600 2012-06-04
Rpm HIGH 9.3
CVE-2011-3378EPSS 6%

RPM 4.4.x through 4.9.x, probably before 4.9.1.2, allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbit…

Fix: after 4.9.1.1
Fix from $1,950 2011-12-24
Rpm HIGH 7.2
CVE-2010-2059

lib/fsm.c in RPM 4.8.0 and unspecified 4.7.x and 4.6.x versions, and RPM before 4.4.3, does not properly reset the metadata of an executable file dur…

Fix: after 4.4.2.3
Fix from $1,950 2010-06-08
Rpm HIGH 7.2
CVE-2010-2198

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrad…

Mitigation only
Fix from $1,950 2010-06-08
Rpm HIGH 7.2
CVE-2010-2199

lib/fsm.c in RPM 4.8.0 and earlier does not properly reset the metadata of an executable file during replacement of the file in an RPM package upgrad…

Mitigation only
Fix from $1,950 2010-06-08
Rpm MEDIUM 5.8
CVE-2010-2197

rpmbuild in RPM 4.8.0 and earlier does not properly parse the syntax of spec files, which allows user-assisted remote attackers to remove home direct…

Mitigation only
Fix from $1,600 2010-06-08
Rpm HIGH 7.2
CVE-2005-4889

lib/fsm.c in RPM before 4.4.3 does not properly reset the metadata of an executable file during deletion of the file in an RPM package removal, which…

Fix: after 4.4.2.3
Fix from $1,950 2010-06-08